CVE Database
/

CVE-2011-3835

Back to search

CVE-2011-3835

Published: Dec 24, 2011

Modified: Aug 6, 2024

PUBLISHED

Description

Multiple cross-site scripting (XSS) vulnerabilities in Wuzly 2.0 allow remote attackers to inject arbitrary web script or HTML via the Referer header to (1) admin/login.php and (2) admin/404.php; the (3) q parameter to search.php; the (4) theme_name parameter to theme_settings.php, (5) extension_name parameter to extension_settings.php, (6) q parameter to search.php, (7) type parameter to comments.php, sort parameter to (8) pages.php and (9) posts.php, and the (10) type and (11) q parameter to media.php in admin/; the sidebar parameter to (12) add_widget.php and (13) widgets.php, id parameter to (14) category_delete.php, (15) comment.php, (16) page_delete.php, and (17) post_delete.php, (18) type parameter to media.php, and (19) id and (20) sidebar parameter to widget_delete.php in mobile/; and the (21) name, (22) email, (23) website, and (24) comment parameters to index.php; and the (25) username parameter to admin/login.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

77929
vdb-entry
x_refsource_OSVDB
77938
vdb-entry
x_refsource_OSVDB
77914
vdb-entry
x_refsource_OSVDB
77931
vdb-entry
x_refsource_OSVDB
77923
vdb-entry
x_refsource_OSVDB
77928
vdb-entry
x_refsource_OSVDB
77925
vdb-entry
x_refsource_OSVDB
77933
vdb-entry
x_refsource_OSVDB
77921
vdb-entry
x_refsource_OSVDB
46163
third-party-advisory
x_refsource_SECUNIA
77922
vdb-entry
x_refsource_OSVDB
77927
vdb-entry
x_refsource_OSVDB
77924
vdb-entry
x_refsource_OSVDB
wuzly-referer-header-xss(71906)
vdb-entry
x_refsource_XF
77935
vdb-entry
x_refsource_OSVDB
77936
vdb-entry
x_refsource_OSVDB
77934
vdb-entry
x_refsource_OSVDB
wuzly-login-xss(71902)
vdb-entry
x_refsource_XF
77930
vdb-entry
x_refsource_OSVDB
77932
vdb-entry
x_refsource_OSVDB
77926
vdb-entry
x_refsource_OSVDB
77937
vdb-entry
x_refsource_OSVDB
77920
vdb-entry
x_refsource_OSVDB
wuzly-multiple-xss(71899)
vdb-entry
x_refsource_XF

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now